Weak Keys of the Full MISTY1 Block Cipher for Related-Key Cryptanalysis

The MISTY1 block cipher has received considerable attention and its security has been thoroughly analyzed since its publication, particularly the European NESSIE project announced that "No weaknesses were found in the selected designs" when making the portfolio of selected cryptographic algorithms including MISTY1. For the very first time, the authors' results exhibit a cryptographic weakness in the full MISTY1 cipher algorithm, particularly from an academic point of view: the cipher does not behave like a random function (in the related-key model); thus it cannot be regarded to be an ideal cipher.